Usage
Information
802.1X authentication is enabled when an interface is connected to the switch. If the host fails
to respond within a designated amount of time, the authenticator places the port in the guest
VLAN.
If a device does not respond within 30 seconds, it is assumed that the device is not 802.1X
capable. Therefore, a guest VLAN is allocated to the interface and authentication for the
device occurs at the next re-authentication interval (
dot1x reauthentication
).
If the host fails authentication for the designated amount of times, the authenticator places the
port in authentication failed VLAN (
dot1x auth-fail-vlan
).
NOTE: The layer 3 portion of guest VLAN and authentication fail VLANs can be created
regardless if the VLAN is assigned to an interface or not. After an interface is assigned a
guest VLAN (which has an IP address), routing through the guest VLAN is the same as any
other traffic. However, the interface may join/leave a VLAN dynamically.
Related
Commands
dot1x auth-fail-vlan
– configures a VLAN for authentication failures.
dot1x reauthentication
– enables periodic re-authentication.
show dot1x interface
– displays the 802.1X information on an interface.
dot1x mac-auth-bypass
Enable MAC authentication bypass. If 802.1X times out because the host did not respond to the Identity Request frame,
FTOS attempts to authenticate the host based on its MAC address.
C-Series, S-Series, Z-Series, S4810
Syntax
[no] dot1x mac-auth-bypass
Defaults
Disabled
Command Modes
INTERFACE
Command History
Version 8.3.11.4
Introduced on the Z9000.
Version 8.4.1.0
Introduced on the C-Series and S-Series.
Usage
Information
To disable MAC authentication bypass on a port, enter the
no dot1x mac-auth-bypass
command.
dot1x max-eap-req
Configure the maximum number of times an extensive authentication protocol (EAP) request is transmitted before the
session times out.
C-Series, E-Series, S-Series, Z-Series, S4810
Syntax
dot1x max-eap-req
number
To return to the default, use the
no dot1x max-eap-req
command.
Parameters
number
Enter the number of times an EAP request is transmitted before a
session time-out. The range is 1 to 10. The default is 2.
1318
Summary of Contents for Force10 Z9000
Page 1: ...FTOS Command Line Reference Guide for the Z9000 System FTOS 9 1 0 0 ...
Page 96: ...96 ...
Page 194: ...194 ...
Page 312: ...312 ...
Page 540: ...540 ...
Page 546: ...546 ...
Page 560: ...560 ...
Page 566: ...566 ...
Page 590: ...action act UpdateCounter param0 1 0x01 param1 0 0x00 output truncated 590 ...
Page 624: ...624 ...
Page 638: ...638 ...
Page 648: ...648 ...
Page 659: ...Related Commands show gvrp displays the GVRP configuration 659 ...
Page 660: ...660 ...
Page 834: ...834 ...
Page 854: ...854 ...
Page 906: ...906 ...
Page 914: ...914 ...
Page 976: ...976 ...
Page 990: ...990 ...
Page 1006: ...1006 ...
Page 1008: ...1008 ...
Page 1026: ...1026 ...
Page 1145: ...10 211 1 2 Outgoing interface list GigabitEthernet 8 0 1145 ...
Page 1146: ...1146 ...
Page 1156: ...1156 ...
Page 1166: ...1166 ...
Page 1180: ...1180 ...
Page 1258: ...1258 ...
Page 1272: ...1272 ...
Page 1394: ...1394 ...
Page 1400: ...1400 ...
Page 1410: ...1410 ...
Page 1424: ...1424 ...
Page 1444: ...1444 ...
Page 1468: ...Version 8 3 8 0 Introduced on the S4810 1468 ...
Page 1470: ...1470 ...